T-Mobile physically severed cable to expel Chinese hackers from network
T-Mobile cybersecurity chief Jeff Simon and colleagues drove to a Bellevue data centre to cut a cable, ending a months-long hunt for intruders linked to the Salt Typhoon campaign.

T-Mobile has revealed that its cybersecurity team physically cut a network cable to expel Chinese hackers from its infrastructure in 2024. The action was taken after staff identified unusual behaviour on a router belonging to an unnamed telecommunications company, marking the final step in a months-long effort to neutralise a sophisticated intrusion.
According to reporting by Bloomberg, T-Mobile’s cybersecurity chief, Jeff Simon, and three colleagues drove to a data centre in Bellevue, Washington, to address the threat. Upon locating the compromised system, the team used a set of scissors to snip the cable connecting the device to the wider network. This physical disconnection was necessary after digital methods failed to remove the intruders from the system.
The incident was part of a broader campaign by the Chinese government-backed hacking group Salt Typhoon. The group targeted hundreds of phone companies, internet giants, and data centre providers, including AT&T, Verizon, Viasat, Charter, and Windstream. The primary objective of the campaign was to collect phone records and information about senior US government officials, including then-presidential candidates.
T-Mobile largely escaped a widescale breach of its network due to early detection of the activity. Cybersecurity staff spent months searching for the suspected hackers within the network before tracing the intrusion to the specific compromised router. The company has not yet provided a direct response or further comment regarding the incident.
The physical severing of the connection highlights the escalating sophistication of state-sponsored cyber threats targeting critical telecommunications infrastructure. While T-Mobile’s response prevented a major data compromise, the incident underscores the challenges faced by major carriers in defending against persistent advanced threats.

